We offer Private Medical Insurance products provided by VitalityHealth Limited and Aviva Limited (Our Insurers or Your Insurer). We will offer advice and will make a recommendation for you that is based on your individual needs for Private Medical Insurance

Insure Your Health is listed as a data controller with the Information Commissioner under registration number Z3588924.

This Notice will inform you of what personal information we collect, how that information is used, where it is transferred, and how you may view and amend such information. You may be assured that we will treat all personal information as confidential and will not process it other than for a legitimate purpose. Steps will be taken to ensure that the information is accurate, kept up to date and not kept for longer than is necessary. Measures will also be taken to safeguard against unauthorised or unlawful processing and accidental loss or destruction or damage to the information.

Securing Your personal data

We have implemented security measures to ensure the secure management of Your personal data. This includes appropriate physical, organisational and technical measures to safeguard Your information. We regularly review these measures and where appropriate, We strengthen and enhance those measures.

Whenever We send Your personal data to You, We will ensure appropriate measures are taken to prevent unauthorised access to Your personal data or interception of Your personal data by anyone not authorised to have it.

If You wish to send any of Your personal data to Us, We strongly recommend You do not send it by open email. Instead, You should select a safe method to provide Your personal data to Us such as recorded post.

How We use personal data

Personal data You give to Us

We may collect personal data from you to the extent necessary to provide You advice, administrative and management services for example

If You would like Us to review Your policy

If You apply for a quote or plan with Us;

If You purchase a policy through Us

If You submit a query to Us, for example by email, telephone or social media, (including where You reference Us in a public social media post); and

If You participate in any marketing activity such as entering a competition, or promotion, or survey.

When You provide personal data to Us about someone else on their behalf

When giving Us information about a family member or another person, You confirm that they have appointed You to act on their behalf including giving You consent to instruct Us to process their personal data, to receive this data protection notice on their behalf and to inform them about the way in which We will process their personal data.

Personal data We receive about You from other external sources

We may receive information about You from other people in order to deliver our products and services to You. This could include (but is not limited to):

Information from analytics providers;

Information from search information providers;

Information from credit reference agencies;

When You are named in an application form or as a dependant under an individual or corporate plan;

When We obtain medical reports; or

Information We create from Your personal data

We will create an internal customer reference number with Your personal data.

We will always ensure that any personal data We receive has been collected lawfully and fairly in accordance with Your rights under the relevant data privacy laws. Where appropriate We will ask for Your consent for the specific use of Your personal data. For the use of Your health or medical information We will ask for Your explicit consent.

Where We are using the personal data that You provide to Us or that has been provided to Us by Your representative, or financial adviser for the purpose of setting up and administering Your plan, We will not seek Your consent for this purpose. This is because the personal data You provide to enable You to purchase the plan will legitimately be used by Us to do what You have requested. Your rights and the protection of Your personal data are not in any way hindered by this approach.

Personal information We hold about You

The information We hold about You may include:

Your name, address, contact details and Your next of kin;

Your health and medical history and current health and or fitness status;

Details about any contact We have had with You such as providing quotes;

Details of the services You have received, claims You have made or treatment You have received;

Feedback that You give to Us regarding the services We have provided or the insurers We use

Recordings of telephone calls between You and Us.

How We use children’s personal data

We do not collect or use children’s personal data except when that information is provided by an adult who has purchased a plan that also covers a child. We do not use children’s information for any marketing activity.

How We use medical and health information

The security of and appropriate use and disclosure of Your health and medical information is of paramount importance to Us.

Insure Your Health will only collect and use sufficient medical information to enable Us to deliver the our services to you.

Insure Your Health will process personal medical and health data provided by You and/or by Your representative as part of Your application for a Health Insurance Plan.

If we collect Your personal medical and health data, We will use this data for the following purposes:

To provide You with a quote

As part of the applications to source quotations from Our Insurers We collect the personal information and with Your or Your Representative’s explicit consent we also capture Your medical history. This information is required for Us to assess your individual requirements, source quotes, identify any additional conditions or exclusions that may need to be applied and make a recommendation that is based on your needs.

We may use information provided by healthcare professionals (Your GP or Your Healthcare Specialist) to gain further information on Your medical health to ensure the cover given is adequate and any necessary exclusions are identified.

For underwriting

During the application process We may be required to share your Medical History with Our Insurers Underwriting Teams for them to identify any additional conditions or exclusions that need to be applied. Manual underwriting may be performed in either the UK or South Africa by underwriters using Your risk profile, applying exclusions, identifying non-disclosures, and reviewing additional medical information received from either our own medical collection specialists or a medical third party.

To set up and administer Your plan

To confirm the purchase of a plan the necessary personal information and medical history is submitted to the chosen Insurer. This will be on terms that are approved by the Information Commissioner and the Insurer will then issue You with a welcome pack which will include a copy of their privacy notice.

To renew or continue Your plan annually

Unless You tell Us or Your Insurer otherwise Your Insurer will renew or continue Your plan and adjust Your premium and coverage amount according to the terms of Your plan. Us and Your insurer will continue to use the data You have previously provided Us.

To communicate with You

We will communicate with You via email, post, telephone, SMS text and social media depending on Your communication preferences and/or the methods You have chosen.

For compliance

To ensure We are compliant with legal and regulatory obligations, We will use Your data, this will include reviewing calls between You and Us. This also helps Us to train our staff and to improve performance.

To carry out data modelling, profiling or statistical analysis

We will use data modelling, profiling and statistical analysis of our customer base for future campaigns to improve the products, services or features We may offer You now or in the future in order to meet Your needs.

Who We share Your personal data with

Disclosure for regulatory or legal purposes

Insure Your Health will only share Your personal data with other companies or organisations where there is a legitimate reason for doing so. For example We are obligated to provide information to specific Government departments such as HM Revenue and Customs and to regulatory bodies who govern our activity such as the Prudential Regulation Authority, Financial Conduct Authority and the Financial Ombudsman Service.

Insure Your Health is an appointed representative of Vitality Corporate Services and may be required to share your personal data with Vitality Corporate Services Limited if required as part of their internal audit activity.

Sharing Your Personal Information with Our Insurers

In order to source quotes, policy conditions and exclusions and complete the purchase of a Health Insurance policy, it is necessary for Us to share the required personal information that is collected from You or Your representative with Our Insurers. It may also be necessary to share your Medical History as this allows the insurer to identify any additional conditions or exclusions that need to be applied.

For legitimate business processes such as Audit Activity, Regulatory Compliance and Legal (including dealing with claims) We may share Your personal information and your Medical History with Your Insurer if it is necessary for them to complete their investigation.

Our use of other companies to provide our products and services to You

We use third party services for areas such as infrustructure and support. This helps us to provide a better and more secure service to customers. When using third-parties, we ensure that there is an agreement in place that meets our standards and legal requirements for data protection. Our Service Providers are listed below;

Criterion IT – Information Technology infrustructure support

Sungard Availability Services – Business Disaster Recovery Solution

Shredit Limited – Confidential Waste Disposal

Eckoh Uk Ltd – Call Recording Software Support

Companies who work under contracts with Us may process your personal data outside of the European Economic Area. This will be on terms that are in line with Data Protection Requirements and adhere to the Information Commissioners Office guidance. Your rights and confidentiality are protected in the same way as they would be if Your personal data was processed in the UK.

Retaining Your personal and health information

We will normally only keep Your personal data for as long as necessary to provide You with the services You’ve chosen and to ensure We meet our regulatory obligations. This means that We will normally hold Your plan information and the personal data We have collected during the term of the plan for seven years after your plan has finished.

At the end of this time period We will fully anonymise all personal data that identifies You or could be used to identify You. We will also ensure that any of the suppliers who have processed Your personal data throughout the term of Your plan delete Your personal data from their systems.

Your legal rights

The General Data Protection Regulation and the Data Protection Act 2018 makes provision for a number of rights under which You are entitled to make a claim. Insure Your Health is committed to ensuring You are given access to these rights and will ensure that this is done appropriately and in compliance with privacy law.

Data subject access requests

Under the General Data Protection Regulation You have the right to ask Insure Your Health to confirm whether or not Your personal data is being processed, and, where it is being processed, to be provided with access to Your personal data and the following information:

The purpose(s) of the processing;

The categories of personal data concerned;

The recipients or categories of recipient to whom Your personal data has been or will be disclosed, in particular recipients in different countries or international organisations;

Where possible, the period for which the personal data will be stored, or, if this is not possible, the criteria used to determine the storage period;

Where Your personal data is not collected from You, any available information about the sources of such information; and

The details of any automated decision-making or profiling being done on Your personal data, meaningful information about the logic involved, and the consequences of such processing for You.

Where Your personal data is transferred to a third country or to an international organisation You have the right to be informed how appropriate safeguards have been used to transfer Your personal information.

If You request it Insure Your Health will provide You with a copy of Your personal data undergoing processing by Us. This would be issued to you by post and by recorded delivery.

If You require access to Your personal data that We have disclosed to a company, and that company is also a data controller, You will need to ask them directly to provide Your personal data.

Portability of personal data

You have the right to receive personal data about You that You have provided to Insure Your Health in a structured, commonly used electronic format. You also have the right to transmit that personal data to a different data controller company and, if it is technically feasible, Insure Your Health will try to transmit Your personal data to such other data controller company. Please note that this attempt may be restricted due to the incompatibility of the various customer record keeping databases.

Withdrawing Your consent

Where We rely upon Your consent to process your personal data, You have the right to withdraw Your consent at any time. From the time that We receive such withdrawal of consent Vitality will stop the processing of Your personal data relating to the consent. Where We have a statutory, regulatory or contractual obligation to process Your personal data We may not be able to meet Your request. You should be aware that if You do withdraw consent for the processing of Your personal data We may not be able to continue to service Your plan with Us.

Your right to be forgotten

You have the right to ask Insure Your Health to erase Your personal data without undue delay and Insure Your Health is obliged to do this where one of the following grounds applies:

Your personal data is no longer necessary in relation to the purposes for which it was collected or otherwise processed;

You withdraw consent on which the processing is based and where there is no other legal ground for the processing;

You object to the processing and there are no overriding legitimate grounds for the processing or Your personal data has been unlawfully processed; or

Your personal data must be erased to comply with a legal obligation.

The right to be forgotten shall not apply to the extent that processing is necessary in order to:

Exercise the right of freedom of expression and information;

Comply with a legal obligation that requires processing in the United Kingdom; or

Establish, exercise or defend a legal claim.

Rectification

You have the right to ask Insure Your Health to rectify any personal data about You without undue delay. Taking into account the purposes of the processing, You have the right to have incomplete personal data completed, including by providing a supplementary information statement.

Restriction on processing

In specified circumstances You have the right to restrict the processing of Your personal data. These are:

You contest the accuracy of Your personal data held by Insure Your Health and restrict the processing to enable Insure Your Health to verify the accuracy;

You request restricted processing of Your personal data instead of erasing it because You believe it to be unlawful processing;

Insure Your Health no longer requires Your personal data for its processing purposes but You require it to establish, exercise or defend a legal claim; or

Where You object to the use of Your personal data for profiling or marketing purposes, and our legitimate grounds for this processing does not override Your rights.

Where Insure Your Health applies restrictions on processing Your personal data, apart from storage, the establishment or exercise of legal defence, or the protection of the rights of another individual, Insure Your Health shall seek Your consent prior to restarting any processing of the restricted personal data.

You have the right to object to automated decision making and profiling

You have the right to object to automated decision making where the outcome may have a legal or other significant impact on You. Insure Your Health does not conduct any automated decision making or profiling.

Marketing

Our Insurers constantly review their products as they wish to provide innovative and relevant insurance options to Our customers. We are also always looking at new innovative offers that You may want to take advantage of, so We would like to keep You informed about all of these exciting new offers.

You have the right to object to the use of Your personal data for marketing purposes and Insure Your Health is obligated to ensure marketing information is not sent to You if You assert this right.

If You do give Us Your permission to send marketing information to You We will provide You with the opportunity to change Your mind every time we contact you. We will communicate with You via telephone, email, post, SMS text and social media depending on Your communication preferences and/or the methods You have chosen.

Data Protection Complaints

We want all of our members to be happy with the way their personal data and health or medical information has been processed by Us. If You are unhappy about the way We have managed Your personal data We would like to know about this. We are constantly striving to ensure We do the right thing, and We would like to be able to put things right.

If You have any queries in respect of Your Data Protection rights or the way Your personal data is processed by Insure Your Health please call Us on 0800 313 4944, email Us at: data.protection@insureyourhealth.co.uk or write to Us at: